Re: [dm-devel] [PATCH 1/1] dm: add message command to disallow device open

From: Daniil Lunev
Date: Wed Aug 03 2022 - 19:38:54 EST


> I thought you were trying to defend against path traversal attacks, not
> arbitrary code execution? If your threat model includes arbitrary code
> execution by root, you really need to be using SELinux.
Hm, this is actually a very good point which we somehow missed, hm.
Thanks for pointing that out, let me think on that